What we do in this area
Corporate compliance is the work of turning what legislation expects of a company into its daily operation. The weight of this heading at our office is the compliance process under the Personal Data Protection Law No. 6698 (KVKK): drawing up the personal data processing inventory, preparing privacy notices and explicit consent texts, VERBİS registration, writing the retention and destruction policy and internal directives, and attaching data processing addenda to supplier contracts. Internal rules on disciplinary and ethics procedures are also handled within this scope.
The work proceeds along the advisory axis rather than litigation and is usually part of a corporate legal advisory relationship. For contract structuring in general, see commercial contracts; for the company law side, see commercial and company law.
KVKK compliance is a matter of process, not documents
The picture most frequently encountered in practice is a privacy notice taken from the internet being placed on the website and compliance being assumed complete. What the Law requires, however, is that the company knows which data it processes, for what purpose and on which legal basis, and can document this. That is why the work starts at the same place in every company: the data inventory. Which unit collects which data, where it stores it, to whom it transfers it, when it deletes it; every text written before this table exists rests on assumption.
Once the inventory is drawn up, each processing activity is matched with the processing conditions in Articles 5 and 6 of the Law. Explicit consent is only one of these conditions; where another processing condition exists, asking for explicit consent is unnecessary and leaves the company in a difficult position if the consent is withdrawn. VERBİS registration depends on the applicable Board exemptions. For controllers whose main activity is not processing special categories of data, the general size exemption requires both no more than fifty employees annually and an annual balance sheet no greater than TRY 100 million; exceeding either threshold removes that exemption. Under Decision 2025/1572, controllers whose main activity is processing special categories of data may also qualify for an exemption if they have no more than ten employees annually and an annual balance sheet no greater than TRY 10 million. Other exemptions and the applicable calculation rules must also be checked.
The set of documents prepared
| Document | Function |
|---|---|
| Personal data processing inventory | The basis of compliance; the VERBİS notification and all texts are fed from it |
| Privacy notices | Information under Article 10 KVKK, subject to Article 28 exceptions |
| Explicit consent texts | Only for activities where no other processing condition exists |
| Retention and destruction policy | Sets how long data is kept and how it is destroyed |
| Special categories of data policy | Additional measures for sensitive categories such as health data |
| Disciplinary and ethics directive | The framework for the internal reporting, investigation and sanction process |
| Data processing addendum | The contract annex signed with a supplier that processes data on the company's behalf |
Supplier contracts and data processing addenda
The data security obligation (Article 12 KVKK) is not limited to the company's own systems. A supplier providing payroll, server hosting, courier or call centre services becomes a data processor when it processes data on the company's behalf and is liable for security jointly with the data controller. This relationship is documented through appropriate contractual provisions, which may be in the main contract or an addendum: the subject and duration of the processing, the security measures to be taken, the use of sub-processors, the right of audit and the return or destruction of the data when the contract ends are regulated in this addendum. In relationships involving transfers abroad, the transfer regime in Article 9 of the Law is assessed separately; this regime was amended in 2024 by Law No. 7499 and a standard contract procedure was introduced.
Disciplinary and ethics procedures
Internal directives are not written for data protection alone. The disciplinary procedure, the ethics reporting channel and the internal investigation procedure determine both the lawfulness of the measure applied to the employee and the company's ability to prove its case in a possible termination. A sanction imposed without taking the employee's defence turns against the company in a later reinstatement action. Because of this link, internal directives are structured together with the labour law side.
The moment of breach or request: the plan is written in advance
What to do when a data breach occurs is not decided on the day. Under Board decisions, notification of the breach to the Authority and to the affected persons is subject to short time limits; who will decide, how records will be kept and how the notification will be made are written in advance into a response plan. Requests from data subjects must also be answered within thirty days at the latest (Article 13 KVKK); who will receive the request and how the response will be prepared are regulated in the internal directive.
This is general information; obligations vary according to the company's scale and the data it processes.
The page where we describe the process in detail: Our working process.
What people ask about this area
Is KVKK compliance a one-off project?
Am I required to register with VERBİS?
Are a privacy notice and an explicit consent form the same thing?
Can we not just use ready-made texts we found on the internet?
If your question is not hereContact

